b58e57
#%PAM-1.0
b58e57
auth	   required	pam_sepermit.so
b58e57
auth       substack     password-auth
b58e57
auth       include      postlogin
b58e57
# Used with polkit to reauthorize users in remote sessions
b58e57
-auth      optional     pam_reauthorize.so prepare
b58e57
account    required     pam_nologin.so
b58e57
account    include      password-auth
b58e57
password   include      password-auth
b58e57
# pam_selinux.so close should be the first session rule
b58e57
session    required     pam_selinux.so close
b58e57
session    required     pam_loginuid.so
b58e57
# pam_selinux.so open should only be followed by sessions to be executed in the user context
b58e57
session    required     pam_selinux.so open env_params
b58e57
session    required     pam_namespace.so
b58e57
session    optional     pam_keyinit.so force revoke
b58e57
session    include      password-auth
b58e57
session    include      postlogin
b58e57
# Used with polkit to reauthorize users in remote sessions
b58e57
-session   optional     pam_reauthorize.so prepare